New issue
Advanced search Search tips

Issue 767048 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: pictures not displaying when youtube notifications sent: Version 60.0.3112.113 (Official Build) (32-bit)

Reported by dww...@gmail.com, Sep 20 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [x.x.x.x] + [stable, beta, or dev]
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

Since yesterday, many notifications have the image blocked, not all the 
time, but mostly, say 75%.  They still open and launch however.  This is the first time this has happened on this scale.  Thanks for looking into it.

Here is am example:

https://mail.google.com/mail/u/0/?tab=wm#inbox/15e9f451ea6ba86e



 

Comment 1 by dww...@gmail.com, Sep 20 2017

In the past, images that were NOT available in the notification, would NOT launch.
This is not the case now.  Thanks for your attention to this...

Dave Williams

Comment 2 by palmer@chromium.org, Sep 20 2017

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
This doesn't sound like a security vulnerability. But it's hard for me to tell, because there is nothing in the report that enables me to see or understand the problem.

(The link https://mail.google.com/mail/u/0/?tab=wm#inbox/15e9f451ea6ba86e is a link to a message in your Gmail, which I can't see, and therefore when I click on it Gmail just opens my own inbox.)

I suggest filing a new issue, with screenshots and/or concrete reproduction steps. Also, unless your own or some else's private information is being leaked to 3rd parties, it doesn't sound like the issue is security-related.

Comment 3 by dww...@gmail.com, Sep 20 2017

Thanks for reviewing the problem.

To create the issue, open gmail, select the entry from the inbox, and the
following is displayed...
As you can see the image is blanked out.  This used to happen once in
awhile.
However, you can launch the video.

The only problem is the graphic with the video is blank.

Please advise, thanks...

Sign in to add a comment